# Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration

> Microsoft Threat Intelligence has attributed a malware-less, identity-driven cloud breach campaign to a newly tracked actor designated Storm-2949. The actor abuses Microsoft Entra Self-Service Password Reset (SSPR) combined with help-desk and end-user social engineering to seize accounts and bypass multi-factor authentication, then weaponises legitimate Azure RBAC permissions, Microsoft Graph enumeration, App Service publishing profiles, Storage account keys, Key Vault secrets, and Azure VM Run Command to perform mass data theft from Microsoft 365 and Azure. Persistence is established by deploying ConnectWise ScreenConnect via the VM Run Command extension after disabling Microsoft Defender for Endpoint, producing a full cloud-wide compromise without dropping traditional malware.

- **Published:** 2026-05-19T12:00:00Z
- **Last reviewed:** 2026-05-19T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0529
- **ID:** TL-2026-0529
- **Severity:** CRITICAL
- **Category:** CLOUD
- **Status:** ACTIVE
- **Actor:** Storm-2949
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Storm-2949 is a financially-motivated and intrusion-for-impact threat cluster first publicly named by Microsoft Threat Intelligence in May 2026. The cluster is distinguished by an exclusively cloud-native kill chain that abuses native Microsoft Entra ID and Azure Resource Manager (ARM) features rather than custom malware, allowing the actor to operate inside the trust boundary of victim tenants and largely evade endpoint-centric detection.

Initial Access — Storm-2949 acquires a foothold by abusing Microsoft Entra Self-Service Password Reset (SSPR). The actor first harvests target identities and verification artefacts (mobile numbers, alternative email addresses, security questions, manager attributes) through pretext calls to corporate help desks and through reconnaissance of public-facing directories (LinkedIn, GitHub, conference rosters). With those artefacts the actor performs an SSPR flow against the victim tenant''s default SSPR endpoint (passwordreset.microsoftonline.com), satisfies the verification challenges (frequently using SIM-swapped or social-engineered MFA push fatigue), and resets the victim''s primary credential. Because SSPR satisfies MFA registration claims, the actor effectively bypasses Conditional Access MFA enforcement on subsequent logins. In several incidents the actor also social-engineered help-desk operators into manually clearing the targeted user''s MFA methods, achieving an MFA reset by proxy.

Discovery & Resource Development — Once authenticated, the actor performs deep tenant enumeration through Microsoft Graph using the standard delegated permissions of the compromised principal: User.Read.All, Group.Read.All, Application.Read.All, RoleManagement.Read.Directory and Directory.Read.All. Microsoft observed Graph traffic from non-corporate egress points (residential proxy and commercial VPN ranges) listing users, groups, directory role assignments, service principals, application consents, conditional access policy names and named locations. Tenant inventory data is staged to attacker-controlled OneDrive accounts or compressed in memory and exfiltrated over HTTPS to Cloudflare-worker fronted infrastructure.

Privilege Escalation — In tenants where the compromised user holds eligible Privileged Identity Management (PIM) roles, the actor activates Global Reader, Application Administrator, Cloud Application Administrator or Privileged Authentication Administrator and bridges from Entra ID into Azure subscriptions by abusing pre-existing RBAC role assignments such as Owner, Contributor, User Access Administrator, Storage Account Key Operator, Key Vault Administrator and Virtual Machine Contributor scoped at the subscription or management group level. Where direct privileges are absent, the actor adds new client secrets or certificates to existing privileged enterprise applications and authenticates as the service principal, taking advantage of the fact that service principal sign-ins are often exempt from interactive Conditional Access policies.

M365 Data Theft — The actor performs mass enumeration of OneDrive for Business and SharePoint Online sites using the Graph endpoints /v1.0/drives/{driveId}/root/search, /sites/{siteId}/lists, and /me/drive/recent. Files matching a hard-coded keyword list (passwords, secret, customer, contract, vpn, ssh, m&a, financials, source, .pem, .pfx, .kdbx, .ovpn) are downloaded in chunks. Exchange Online mailboxes are accessed using IMAP/EWS where legacy authentication is still enabled, or via Graph Mail.Read.All on consent-phished applications.

Azure Data Plane Theft — Within Azure, Storm-2949 systematically targets four data services. (1) Azure Storage — the actor issues microsoft.Storage/storageAccounts/listkeys/action against every accessible storage account, then uses the listed keys to enumerate and download blob containers and file shares with azcopy. (2) Azure SQL — to defeat IP allow-listing the actor calls microsoft.sql/servers/firewallrules/write to add a transient rule (commonly 0.0.0.0-255.255.255.255 named ''ClientIPAddress_2026-05-12_18-04-22''), authenticates with Entra credentials of synced sql_admin accounts, and bulk-exports tables with sqlcmd -Q ''select * ...'' bcp. (3) Azure Key Vault — the actor issues microsoft.KeyVault/vaults/secrets/getSecret/action and microsoft.KeyVault/vaults/keys/wrap/action against every accessible vault, retrieving database connection strings, application secrets and code-signing keys. (4) Azure App Service — the actor abuses microsoft.Web/sites/publishxml/action to download publishing profiles and then either deploys a webshell via Kudu (/api/zip, /DebugConsole) or reads connection strings and app settings to pivot back into databases.

VM Compromise & Persistence — On selected high-value Azure VMs the actor calls microsoft.Compute/virtualMachines/runCommand/action (or installs the VMAccess extension to reset the local administrator) to execute a sequence of PowerShell commands that: (a) tamper Microsoft Defender for Endpoint (Set-MpPreference -DisableRealtimeMonitoring $true, Set-MpPreference -DisableTamperProtection $true where Tamper Protection is configurable, and stopping the WinDefend service via sc.exe stop windefend after taking ownership of the service registry key); (b) download and install ConnectWise ScreenConnect MSI from an attacker-controlled Azure Front Door endpoint; (c) configure the ScreenConnect agent against attacker-controlled relay tenants instance-relay.screenconnect[.]com:8041 hosted under attacker-registered ConnectWise Control trials; (d) create a scheduled task ''Microsoft\Windows\UpdateOrchestrator\Heartbeat'' for persistence. ScreenConnect provides interactive RDP-equivalent access with native binary signed by ConnectWise, defeating signature-based detection.

Impact — Microsoft documented terabyte-scale exfiltration of M365 and Azure data, Key Vault secret theft used to pivot into downstream SaaS services, and in two incidents the actor used the same access to read Microsoft Sentinel and Defender data, identify which of their actions had triggered alerts, and re-tool. No ransomware or wiper has been deployed by Storm-2949 to date; observed motivations are data theft, extortion, and follow-on access brokering. The campaign is broadly cross-vertical with confirmed victims in technology, professional services, healthcare and the public sector across North America and Western Europe.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1589.001 Gather Victim Identity Information: Credentials
- T1589.003 Gather Victim Identity Information: Employee Names
- T1583.006 Acquire Infrastructure: Web Services
- T1588.002 Obtain Capabilities: Tool
- T1078.004 Valid Accounts: Cloud Accounts
- T1199 Trusted Relationship
- T1651 Cloud Administration Command
- T1648 Serverless Execution
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1098.001 Account Manipulation: Additional Cloud Credentials
- T1098.003 Account Manipulation: Additional Cloud Roles
- T1136.003 Create Account: Cloud Account
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1219 Remote Access Tools
- T1484.002 Domain or Tenant Policy Modification: Trust Modification
- T1685 Disable or Modify Tools
- T1685.002 Disable or Modify Cloud Log
- T1578.005 Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
- T1564.011 Hide Artifacts: Ignore Process Interrupts
- T1621 Multi-Factor Authentication Request Generation
- T1556.006 Modify Authentication Process: Multi-Factor Authentication
- T1552.005 Unsecured Credentials: Cloud Instance Metadata API
- T1552.001 Unsecured Credentials: Credentials in Files
- T1528 Steal Application Access Token
- T1606.002 Forge Web Credentials: SAML Tokens
- T1526 Cloud Service Discovery
- T1538 Cloud Service Dashboard
- T1087.004 Account Discovery: Cloud Account
- T1069.003 Permission Groups Discovery: Cloud Groups
- T1619 Cloud Storage Object Discovery
- T1550.001 Use Alternate Authentication Material: Application Access Token
- T1550.004 Use Alternate Authentication Material: Web Session Cookie
- T1530 Data from Cloud Storage
- T1213.002 Data from Information Repositories: SharePoint
- T1114.002 Email Collection: Remote Email Collection
- T1102 Web Service
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1537 Transfer Data to Cloud Account
- T1657 Financial Theft

## Sources

- [How Storm-2949 turned a compromised identity into a cloud-wide breach](https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/)
- [Microsoft Threat Actor Naming Taxonomy — Storm prefix](https://learn.microsoft.com/en-us/security/threat-intelligence/microsoft-threat-actor-naming)
- [Configure Microsoft Entra self-service password reset (SSPR)](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-sspr-deployment)
- [Plan a Conditional Access deployment](https://learn.microsoft.com/en-us/entra/identity/conditional-access/plan-conditional-access)
- [Azure RBAC built-in roles](https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles)
- [Run scripts in a Linux/Windows VM by using Run Command](https://learn.microsoft.com/en-us/azure/virtual-machines/run-command-overview)
- [Microsoft Defender for Endpoint Tamper Protection](https://learn.microsoft.com/en-us/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection)
- [MITRE ATT&CK — Cloud Accounts (T1078.004)](https://attack.mitre.org/techniques/T1078/004/)
- [MITRE ATT&CK — Account Manipulation: Additional Cloud Credentials (T1098.001)](https://attack.mitre.org/techniques/T1098/001/)
- [MITRE ATT&CK — Serverless Execution (T1648)](https://attack.mitre.org/techniques/T1648/)
- [CISA — Identity, Credential and Access Management for Cloud](https://www.cisa.gov/resources-tools/resources/identity-credential-and-access-management-icam-reference-architecture)
- [ConnectWise ScreenConnect Abuse for Persistence — Industry Reporting](https://www.connectwise.com/company/trust/security-bulletins)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0529
